Home Rogue Websites Best-av1-protect.info

Best-av1-protect.info

Posted: May 4, 2009

Best-av1-protect.info is a browser hijacker promoting the rogue anti-spyware application Anti-virus-1 (also known as Antivirus 1). Due to trojan viruses infiltrating your system and modifying browser settings, your internet surfing becomes redirected to the Best-av1-protect.info domain. Here you are either bombarded by aggressive advertisement recommending purchase and download of Anti-virus-1, or a fake online scanner reports numerous counterfeit parasites on your system in order to scare you into purchasing and installing Anti-virus-1.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Documents and Settings%\All Users\Application Data\AV1
    2 %Documents and Settings%\All Users\Application Data\AV1\AV1.cab
    3 %Documents and Settings%\All Users\Application Data\AV1\av1.exe
    4 %Documents and Settings%\All Users\Application Data\AV1\AV1i.exe
    5 %Documents and Settings%\All Users\Application Data\AV1\AV1i2.exe
    6 %Documents and Settings%\All Users\Application Data\AV1\QWProtect.dll
    7 %Documents and Settings%\All Users\Application Data\AV1\svchost.exe
    8 %Documents and Settings%\All Users\Desktop\Anti-virus-1.lnk
    9 %Documents and Settings%\All Users\Start Menu\Programs\Anti-virus-1
    10 %Documents and Settings%\All Users\Start Menu\Programs\Anti-virus-1\Anti-virus-1.lnk
    11 %Documents and Settings%\All Users\Start Menu\Programs\Anti-virus-1\Uninstall.lnk

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\AV1HKEY_CURRENT_USER\Software\AV1\AV1\{F275E931-AFEC-4f70-B0D4-CC2731B945E0}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{70FEAD04-A7FD-4B89-B814-8A8251C90EF7}HKEY..\..\..\..{RegistryKeys}HKEY_CLASSES_ROOT\AppID\QWProtect.DLLHKEY_CLASSES_ROOT\AppID\{29256442-2C14-48CA-B756-3EE0F8BDC774}HKEY_CLASSES_ROOT\CLSID\{70FEAD04-A7FD-4B89-B814-8A8251C90EF7}HKEY_CLASSES_ROOT\Interface\{051C9A06-FB08-486F-B09B-8B33B261637D}HKEY_CLASSES_ROOT\QWProtect.QWProtectBHOHKEY_CLASSES_ROOT\TypeLib\{512E801E-2F02-4ADE-ACAA-58F08A22B2F8}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Monitor calibration"
Loading...